New scan:

Malware Scanner report for happybabydelights.com

Malicious/Suspicious/Total urls checked
0/0/14
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

HaCked by Malaysia Security Tester  (49 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://happybabydelights.com/
200 OK
Content-Length: 1476
Content-Type: text/html
suspicious
Deface/Content modification. The following signature was found: HaCked by Malaysia Security Tester

<html>
<head><body bgcolor="black">
<link rel="icon"
type="image" href="http://us.123rf.com/450wm/prapass/prapass1203/prapass120300083/12661324-malaysia-flag-palm-print-isolated-on-white-background.jpg" />
<title>HaCked by Malaysia Security Tester</title>
<center><img src="http://i.imgur.com/CVoQqYX.png" width="879" height="586">
</center>
<meta name="description" content="Hacked By Zerk">
<meta name="keywords" content="Zerk">
<meta name="author" content="Malaysian Security Tester">
<style>
a:link, a:visited {font-weight:normal; text-decoration:none; color:0080FF;}
a:hover {font-weight
...[1023 bytes skipped]...


http://happybabydelights.com/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Fri, 09 May 2014 10:00:10 GMT
Location: http://www.gogvo.com/404.html
Server: Apache
Content-Length: 213
Content-Type: text/html; charset=iso-8859-1
clean
http://www.gogvo.com/404.html
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 May 2014 10:00:10 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 214
Content-Type: text/html
Last-Modified: Fri, 25 Oct 2013 15:15:55 GMT
clean
http://www.joeltherien.com/go/pureleverage
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Fri, 09 May 2014 10:00:11 GMT
Location: http://www.pureleverage.com/launch/15?id=johnnymo
Server: Apache
Content-Length: 0
Content-Type: text/html
X-Powered-By: PHP/5.2.13
clean
http://www.pureleverage.com/launch/15?id=johnnymo
200 OK
Content-Length: 5661
Content-Type: text/html
clean
http://www.pureleverage.com/launch/style/15/js/modernizr-2.6.2.min.js
200 OK
Content-Length: 15414
Content-Type: text/javascript
clean
https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js
200 OK
Content-Length: 94840
Content-Type: text/javascript
clean
http://happybabydelights.com/launch/style/15/js/jquery.backstretch.min.js
HTTP/1.1 302 Found
Connection: close
Date: Fri, 09 May 2014 10:00:14 GMT
Location: http://www.gogvo.com/404.html
Server: Apache
Content-Length: 213
Content-Type: text/html; charset=iso-8859-1
clean
http://www.gogvo.com/test404page.js
HTTP/1.1 404 Not Found
Connection: close
Date: Fri, 09 May 2014 10:00:15 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 214
Content-Type: text/html
Last-Modified: Fri, 25 Oct 2013 15:15:55 GMT
clean
http://www.joeltherien.com/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Fri, 09 May 2014 10:00:15 GMT
Location: http://gvo19363.gvodatacenter.com/404.html
Server: Apache
Content-Length: 226
Content-Type: text/html; charset=iso-8859-1
clean
http://gvo19363.gvodatacenter.com/404.html
500 Can't connect to gvo19363.gvodatacenter.com:80 (Bad hostname)
Content-Length: 184
Content-Type: text/plain
clean
http://gvo19363.gvodatacenter.com/test404page.js
500 Can't connect to gvo19363.gvodatacenter.com:80 (Bad hostname)
Content-Length: 184
Content-Type: text/plain
clean
http://happybabydelights.com/launch/js/leads.min.js
HTTP/1.1 302 Found
Connection: close
Date: Fri, 09 May 2014 10:00:16 GMT
Location: http://www.gogvo.com/404.html
Server: Apache
Content-Length: 213
Content-Type: text/html; charset=iso-8859-1
clean
http://www.gogvo.com/js/cpa_with_cookies.js
200 OK
Content-Length: 1274
Content-Type: application/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: happybabydelights.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 May 2014 10:00:09 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1476
Content-Type: text/html
Last-Modified: Tue, 01 Apr 2014 14:09:54 GMT

...1476 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: happybabydelights.com
Referer: http://www.google.com/search?q=happybabydelights.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=happybabydelights.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://happybabydelights.com/

Result: happybabydelights.com is not infected or malware details are not published yet.